# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Identity Services Certificate Profiles API version: 1.0.0 extends: openapi/palo-alto-networks-certificate-profiles-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 10 - target: $.paths['/certificate-profiles'].get update: x-apievangelist-phrasing: intent: List certificate profiles effect: read questions: - Which certificate profiles are configured in a given folder? - Can I find a certificate profile by name within a snippet or device? instructions: - text: List certificate profiles in folder {folder}. slots: folder: query.folder - text: Find certificate profile {name} on device {device}. slots: name: query.name device: query.device method: generated generated: '2026-09-26' - target: $.paths['/certificate-profiles'].post update: x-apievangelist-phrasing: intent: Create a certificate profile effect: write questions: - How do I create a certificate profile with trusted CA certificates? - Can a new certificate profile block expired or unknown certs and use OCSP? instructions: - text: Create certificate profile {name} with CA certificates {ca_certificates}. slots: name: requestBody.name ca_certificates: requestBody.ca_certificates - text: Add certificate profile {name} using CAs {ca_certificates} with OCSP {use_ocsp} and block expired {block_expired_cert}. slots: name: requestBody.name ca_certificates: requestBody.ca_certificates use_ocsp: requestBody.use_ocsp block_expired_cert: requestBody.block_expired_cert method: generated generated: '2026-09-26' - target: $.paths['/certificate-profiles/{id}'].get update: x-apievangelist-phrasing: intent: Get a certificate profile effect: read questions: - How do I view one certificate profile's settings by ID? - What CA certificates and revocation checks does a specific certificate profile use? instructions: - text: Get certificate profile {id}. slots: id: path.id - text: Show the revocation settings of certificate profile {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/certificate-profiles/{id}'].put update: x-apievangelist-phrasing: intent: Update a certificate profile effect: write questions: - How do I change the CA list or CRL settings on an existing certificate profile? - Can I adjust the OCSP timeout on a certificate profile I already created? instructions: - text: Update certificate profile {id} named {name} to use CAs {ca_certificates}. slots: id: path.id name: requestBody.name ca_certificates: requestBody.ca_certificates - text: Set OCSP receive timeout to {ocsp_receive_timeout} on existing profile {id} ({name}, CAs {ca_certificates}). slots: ocsp_receive_timeout: requestBody.ocsp_receive_timeout id: path.id name: requestBody.name ca_certificates: requestBody.ca_certificates method: generated generated: '2026-09-26' - target: $.paths['/certificate-profiles/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a certificate profile effect: destructive questions: - How do I delete a certificate profile? - Can I remove a certificate profile by its ID? instructions: - text: Delete certificate profile {id}. slots: id: path.id - text: Remove the certificate profile with ID {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/certificate-profiles'].get update: x-apievangelist-phrasing: intent: List certificate profiles effect: read questions: - Which certificate profiles exist in a Prisma Access folder? - Can I look up a certificate profile by name? instructions: - text: List certificate profiles in folder {folder} through the SSE config v1 path. slots: folder: query.folder - text: Find the certificate profile named {name} in {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/certificate-profiles'].post update: x-apievangelist-phrasing: intent: Create a certificate profile effect: write questions: - How do I create a certificate profile with my CA certificates? - Can a new certificate profile block expired or unknown certificates? instructions: - text: Create certificate profile {name} in folder {folder} using CA certificates {ca_certificates}. slots: name: requestBody.name folder: query.folder ca_certificates: requestBody.ca_certificates - text: Add cert profile {name} in {folder} with CAs {ca_certificates} and OCSP enabled {use_ocsp}. slots: name: requestBody.name folder: query.folder ca_certificates: requestBody.ca_certificates use_ocsp: requestBody.use_ocsp method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/certificate-profiles/{id}'].get update: x-apievangelist-phrasing: intent: Get a certificate profile effect: read questions: - What CA certificates and revocation checks are in a certificate profile? - Can I view one certificate profile by its ID? instructions: - text: Show certificate profile {id}. slots: id: path.id - text: Get the settings of cert profile {id}. slots: id: path.id method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/certificate-profiles/{id}'].put update: x-apievangelist-phrasing: intent: Modify a certificate profile effect: write questions: - Can I change the CRL or OCSP settings on an existing certificate profile? - How do I swap the CA certificates in a certificate profile I already have? instructions: - text: Modify certificate profile {id} via the SSE config v1 path, keeping name {name} and CAs {ca_certificates}. slots: id: path.id name: requestBody.name ca_certificates: requestBody.ca_certificates - text: Turn on CRL checking ({use_crl}) for cert profile {id}, name {name}, CAs {ca_certificates}. slots: use_crl: requestBody.use_crl id: path.id name: requestBody.name ca_certificates: requestBody.ca_certificates method: generated generated: '2026-10-01' - target: $.paths['/sse/config/v1/certificate-profiles/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a certificate profile effect: destructive questions: - Can I delete a certificate profile I no longer use? - Is a certificate profile removed permanently when deleted? instructions: - text: Delete certificate profile {id} using the SSE config v1 endpoint. slots: id: path.id - text: Remove cert profile {id}. slots: id: path.id method: generated generated: '2026-10-01'